
Zeek detector for QuasarRat
मैलवेयर अक्सर अपने कमांड और कंट्रोल (C2) सर्वर के साथ संचार HTTPS पर छिपाता है। HTTPS में एन्क्रिप्शन आमतौर पर समझौते को इतनी देर तक छिपाए रखता है कि मैलवेयर अपना लक्ष्य पूरा कर ले। यह HTTPS का उपयोग करने वाले मैलवेयर का पता लगाना चुनौतीपूर्ण बनाता है, लेकिन कभी-कभी आपको मौका मिल जाता है, जैसा कि यहाँ QuasarRAT के मामले में है, जो एक Windows रिमोट एक्सेस टूल है जिसे पिछले वर्ष में संयुक्त राज्य में महत्वपूर्ण बुनियादी ढांचे का प्रबंधन करने वाले संगठनों को निशाना बनाने के लिए तैनात किया गया है।
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2024-10-09-18-06-57
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1723831638.402474 CpKJJiDUPEBNMGSC 192.168.100.7 49744 86.136.67.231 1337 - - - tcp QuasarRAT::C2_Traffic_Observed_Cert Potential QuasarRAT C2 - default SSL certificate discovered. - 192.168.100.7 86.136.67.231 1337 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2024-10-09-18-06-57
आप "suri" निर्देशिका में Suricata नियम पा सकते हैं।